BIOC Medium

PowerShell downloads files via BITS

This PowerShell argument is often used to run commands with malicious intent.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Persistence
Status:
Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: BITS Jobs (T1197)
Indicator:

Process action type = execution AND target process cmd = *start-bitstransfer* , *complete-bitstransfer* AND target process name = powershell.exe AND process execution signature = Signed AND process execution signer = Microsoft Corporation Host host os = windows

Preventable: yes